doctor and sole managing director of the laboratory (first data subject) – Complaint Upheld (Austria, 2023)

Complaint Upheld
Datenschutzbehörde6 October 2023Austria
final
Complaint Upheld

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

An Austrian doctor faced a complaint for mishandling personal data but was not fined. This case is significant because it underscores the need for proper data protection practices, especially when handling sensitive information like health data.

What happened

A complaint was upheld against a doctor for failing to protect personal data in an Excel file.

Who was affected

Thousands of individuals whose PCR test results were exposed were affected.

What the authority found

The Austrian data protection authority upheld the complaint but did not impose any fines, indicating a need for better data security measures.

Why this matters

This ruling emphasizes the importance of safeguarding sensitive information and the potential consequences of failing to do so. Healthcare providers must prioritize data security to protect patient information.

GDPR Articles Cited

AI-verified

Art. 5(1)(b) GDPR
Art. 6(1) GDPR
Art. 6(1)(f) GDPR
Art. 12(3) GDPR
Art. 12(4) GDPR
Art. 15(1) GDPR
Art. 15(1)(g) GDPR
Art. 15(3) GDPR
Art. 17(1) GDPR
Art. 17(3) GDPR
Art. 17(3)(a) GDPR
Art. 17(3)(e) GDPR
Art. 58(2)(c) GDPR
View original scraped data
Art. 5(1)(b) GDPR
Art. 6(1) GDPR
Art. 6(1)(f) GDPR
Art. 12(3) GDPR
Art. 12(4) GDPR
Art. 15(1) GDPR
Art. 15(1)(g) GDPR
Art. 15(3) GDPR
Art. 17(1) GDPR
Art. 17(3) GDPR
Art. 17(3)(a) GDPR
Art. 17(3)(e) GDPR
Art. 58(2)(c) GDPR

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

§ 9(1) DSG
§ 31 Mediengesetz

Entities Involved

doctor and sole managing director of the laboratory (first data subject)
laboratory for diagnostics (second data subject)
newspaper company (first controller)
broadcasting company (second controller)
Source verified 24 August 2026
national law identified
Full Legal Summary
Detailed

In August 2021, an unprotected Excel file containing the names and PCR test results of several thousand individuals was sent from the compromised email account of the first data subject, which was administered by the second data subject. The file was then forwarded by a third party to the first and second controller, who reported about the case on 01. September 2021 in their online news portals. On 02. September 2021, the second data subject requested the deletion of the news articles. The first controller forwarded this request alongside their response to the second controller. Both controllers rejected the deletion request on grounds of the journalistic exemption (Medienprivileg) under [https://www.ris.bka.gv.at/eli/bgbl/i/1999/165/A2P9/NOR40201397?Abfrage=Bundesnormen&Kundmachungsorgan=&Index=&Titel=DSG&Gesetzesnummer=&VonArtikel=&BisArtikel=&VonParagraf=9&BisParagraf=&VonAnlage=&BisAnlage=&Typ=&Kundmachungsnummer=&Unterzeichnungsdatum=&FassungVom=&VonInkrafttretedatum=&BisInkrafttretedatum=&VonAusserkrafttretedatum=&BisAusserkrafttretedatum=&NormabschnittnummerKombination=Und&ImRisSeitVonDatum=&ImRisSeitBisDatum=&ImRisSeit=Undefined&ResultPageSize=100&Suchworte=BGBl+I+Nr+24%2f2018&Position=1&SkipToDocumentPage=true&ResultFunctionToken=b49884a7-7ca2-4b7e-b190-c849f2424782 § 9(1) DSG], and also asked further questions about the case. On 09. September 2021, the second data subject requested information from both controllers regarding the processing, transmission and purpose of their data and trade secrets. Only the second controller replied to the request, stating that the data processing was for journalistic purposes and, hence, there was no right to deletion in this specific case under the media law (Mediengesetz). On 10. September 2021, the first data subject requested the provision of all their data under Article 15 GDPR from both controllers. The second controller replied on 11. October 2021, and the first controller on 15. April 2022 by essentially providing

Outcome

Complaint Upheld

A data subject complaint that was upheld by the DPA.

Related Enforcement Actions (0)

No other enforcement actions found for doctor and sole managing director of the laboratory (first data subject) in AT

This is the only recorded action for this entity in this jurisdiction.

Details

Decision Date

6 October 2023

Authority

Datenschutzbehörde

GDPRhub ID

gdprhub-10207

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. doctor and sole managing director of the laboratory (first data subject) - Austria (2023). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: